What is CISA BOD 26-04?
CISA Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk" (10 June 2026), which replaced BOD 22-01's flat KEV deadlines with risk-based timelines.
The directive scores each vulnerability on an agency asset with four decision points: whether the asset is publicly exposed, whether the CVE is in the KEV catalog, whether exploitation is automatable and the technical impact (the last two as documented by CISA's Vulnrichment programme). The combination sets the deadline; the most urgent tier is three days with forensic triage, and the lowest is "fix on system upgrade".
The clock starts when CISA adds the CVE to KEV or when the agency finds it on an asset, whichever comes first, and timelines move when exposure or KEV status changes. It binds federal civilian executive branch agencies; contractors only where their contract says so.
Sources
Related terms
- BOD 22-01CISA Binding Operational Directive 22-01 (November 2021), which created the KEV catalog and required federal agencies to fix listed CVEs by set deadlines. It was revoked on 10 June 2026 by BOD 26-04.
- KEV due dateThe dueDate field on a KEV catalog entry: the deadline by which US federal civilian agencies must apply the required action for that CVE.
- SSVCStakeholder-Specific Vulnerability Categorization: a decision-tree method that turns a few facts about a vulnerability into an action, such as Track, Attend or Act.